[Japanese]
|
JVNDB-2013-000071
|
Oracle Outside In vulnerable to denial-of-service (DoS)
|
Oracle Outside In is a library to decode over 500 file types. Oracle Outside In contains a denial-of-service (DoS) vulnerability.
Takahiro Haruyama of Internet Initiative Japan Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
|
CVSS V2 Severity: Base Metrics 5.0 (Medium) [IPA Score]
- Access Vector: Network
- Access Complexity: Low
- Authentication: None
- Confidentiality Impact: None
- Integrity Impact: Partial
- Availability Impact: None
|
|
IBM Corporation
- IBM WebSphere Portal 6.0.0
- IBM WebSphere Portal 6.0.1
- IBM WebSphere Portal 6.1.0
- IBM WebSphere Portal 6.1.5
- IBM WebSphere Portal 7
- IBM WebSphere Portal 8
Oracle Corporation
- Oracle Fusion Middleware Oracle Outside In Technology version 8.4.1 and earlier
Microsoft Corporation
- Microsoft Exchange Server 2007 SP3
- Microsoft Exchange Server 2010 SP2 and SP3
- Microsoft Exchange Server 2013 Cumulative Update 1
- Microsoft Exchange Server 2013 Cumulative Update 2
|
Please refer to 1660640 provided by IBM for more details about IBM WebSphere Portal.
|
When Oracle Outside In processes a specially crafted Hangul Word Processor file, the process may hang.
|
[Apply an update]
Update to the latest version according to the information provided by the developer.
|
IBM Corporation
Oracle Corporation
Microsoft Corporation
FUJITSU
- FUJITSU Security Information : TA13-225A (in Japanese)
|
- No Mapping(CWE-noinfo) [IPA Evaluation]
|
- CVE-2013-3776
|
- JVN : JVN#68663052
- JVN : JVNTA13-225A (in Japanese)
- National Vulnerability Database (NVD) : CVE-2013-3776
- IPA SECURITY ALERTS : Security Updates Available for Microsoft (August 2013) (in Japanese)
- JPCERT REPORT : JPCERT-AT-2013-0035 (in Japanese)
- @Police : Microsoft Security Bulletin for August 2013 (in Japanese)
- US-CERT Technical Cyber Security Alert : TA13-225
|
- [2013/07/17]
Web page was published
[2013/08/23]
Affected Products : Products were added
Vendor Information : Contents were added
References : Contents were added
[2013/08/28]
Vendor Information : Contents were added
[2014/02/24]
Affected Products : Products were added
Vendor Information : Contents were added
|